CVE-2014-4725

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
mailpoetmailpoet_newsletters
𝑥
≤ 2.6.6
mailpoetmailpoet_newsletters
0.9
mailpoetmailpoet_newsletters
0.9.1
mailpoetmailpoet_newsletters
0.9.2
mailpoetmailpoet_newsletters
0.9.6
mailpoetmailpoet_newsletters
1.0
mailpoetmailpoet_newsletters
1.0.1
mailpoetmailpoet_newsletters
1.1
mailpoetmailpoet_newsletters
1.1.1
mailpoetmailpoet_newsletters
1.1.2
mailpoetmailpoet_newsletters
1.1.3
mailpoetmailpoet_newsletters
1.1.4
mailpoetmailpoet_newsletters
1.1.5
mailpoetmailpoet_newsletters
2.0
mailpoetmailpoet_newsletters
2.0.1
mailpoetmailpoet_newsletters
2.0.2
mailpoetmailpoet_newsletters
2.0.3
mailpoetmailpoet_newsletters
2.0.4
mailpoetmailpoet_newsletters
2.0.5
mailpoetmailpoet_newsletters
2.0.6
mailpoetmailpoet_newsletters
2.0.7
mailpoetmailpoet_newsletters
2.0.8
mailpoetmailpoet_newsletters
2.0.9
mailpoetmailpoet_newsletters
2.0.9.5
mailpoetmailpoet_newsletters
2.1
mailpoetmailpoet_newsletters
2.1.1
mailpoetmailpoet_newsletters
2.1.2
mailpoetmailpoet_newsletters
2.1.3
mailpoetmailpoet_newsletters
2.1.4
mailpoetmailpoet_newsletters
2.1.5
mailpoetmailpoet_newsletters
2.1.6
mailpoetmailpoet_newsletters
2.1.7
mailpoetmailpoet_newsletters
2.1.8
mailpoetmailpoet_newsletters
2.1.9
mailpoetmailpoet_newsletters
2.2
mailpoetmailpoet_newsletters
2.2.1
mailpoetmailpoet_newsletters
2.2.2
mailpoetmailpoet_newsletters
2.2.3
mailpoetmailpoet_newsletters
2.3
mailpoetmailpoet_newsletters
2.3.1
mailpoetmailpoet_newsletters
2.3.2
mailpoetmailpoet_newsletters
2.3.3
mailpoetmailpoet_newsletters
2.3.4
mailpoetmailpoet_newsletters
2.3.5
mailpoetmailpoet_newsletters
2.4
mailpoetmailpoet_newsletters
2.4.1
mailpoetmailpoet_newsletters
2.4.2
mailpoetmailpoet_newsletters
2.4.3
mailpoetmailpoet_newsletters
2.4.4
mailpoetmailpoet_newsletters
2.5
mailpoetmailpoet_newsletters
2.5.1
mailpoetmailpoet_newsletters
2.5.2
mailpoetmailpoet_newsletters
2.5.3
mailpoetmailpoet_newsletters
2.5.4
mailpoetmailpoet_newsletters
2.5.5
mailpoetmailpoet_newsletters
2.5.7
mailpoetmailpoet_newsletters
2.5.8
mailpoetmailpoet_newsletters
2.5.9
mailpoetmailpoet_newsletters
2.5.9.1
mailpoetmailpoet_newsletters
2.5.9.2
mailpoetmailpoet_newsletters
2.5.9.3
mailpoetmailpoet_newsletters
2.5.9.4
mailpoetmailpoet_newsletters
2.6
mailpoetmailpoet_newsletters
2.6:beta
mailpoetmailpoet_newsletters
2.6.1
mailpoetmailpoet_newsletters
2.6.2
mailpoetmailpoet_newsletters
2.6.3
mailpoetmailpoet_newsletters
2.6.4
mailpoetmailpoet_newsletters
2.6.5
𝑥
= Vulnerable software versions